Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
References
Link | Resource |
---|---|
https://github.com/unshiftio/url-parse/commit/53b1794e54d0711ceb52505e0f74145270570d5a | Vendor Advisory |
https://github.com/unshiftio/url-parse/commit/d7b582ec1243e8024e60ac0b62d2569c939ef5de | Vendor Advisory |
https://hackerone.com/reports/384029 | Issue Tracking Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: hackerone
Published: 2018-08-12T22:00:00
Updated: 2018-08-12T21:57:01
Reserved: 2017-12-28T00:00:00
Link: CVE-2018-3774
JSON object: View
NVD Information
Status : Modified
Published: 2018-08-12T22:29:00.220
Modified: 2019-10-09T23:40:37.200
Link: CVE-2018-3774
JSON object: View
Redhat Information
No data.